knez/defender-dump

Microsoft Windows Defender quarantined VMWare and VirtualBox snapshot files

Closed this issue · 0 comments

Thank you very much for this useful program. In a short period of time I had two random corrupted VMWare and VirtualBox virtual machines and could not find the root cause. In both cases one snapshot file was missing. I rebuilt the VM's from scratch as I had no other option.

Today I figured out that Windows Defender moved the snapshots over 20GB to quarantine without an option to restore the files. With your Python application I was at least able to show the files in C:\ProgramData\Microsoft\Windows Defender\Quarantine which confirmed the issue.

Windows Defender is a nightmare when it puts harmless files in quarantine and destroys VM's! Now I've added a folder exception for the VM directories and hopefully this will never happen again.